CVE-2020-9295

CVSS 3.1 Score 4.7 of 10 (medium)

Details

Published Mar 17, 2025
CWE ID 358

Summary

CVE-2020-9295 is a vulnerability affecting FortiOS 6.2, 6.4, and FortiClient 6.2 with AV engine versions 6.00142 and below, 6.00144 and below, and 6.00137 and below respectively. These systems may fail to detect certain malformed or non-standard RAR archives containing malicious files. FortiClient will identify malicious files upon extraction via real-time scanning. FortiGate can detect the malicious archive if Virus Outbreak Prevention is activated. This vulnerability could potentially expose systems to malware if the suspicious files are opened or extracted. Users are advised to upgrade their AV engine versions to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Fortinet FortiClient

Affected Vendors

  • Fortinet